{"id":103625,"date":"2026-07-13T04:25:21","date_gmt":"2026-07-13T04:25:21","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/103625\/"},"modified":"2026-07-13T04:25:21","modified_gmt":"2026-07-13T04:25:21","slug":"fighting-ai-with-ai-requires-enduring-new-approaches","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/103625\/","title":{"rendered":"Fighting AI with AI requires enduring, new approaches"},"content":{"rendered":"<p><a href=\"https:\/\/federalnewsnetwork.com\/cme-event\/federal-insights\/defense-reimagined-cybersecurity-in-the-age-of-intelligent-adversaries\/\" rel=\"nofollow noopener\" target=\"_blank\">Watch the full discussion here.<\/a><\/p>\n<p>The expansion of artificial intelligence capabilities has changed the way agencies work. From the straightforward use of chatbots to the advanced tools like agentic agents, the Trump administration is pushing hard on agencies to use AI to improve how they deliver on their missions.<\/p>\n<p>At the same time, agencies have to keep up with how to govern and manage these models as the speed of release increases. And then there is the security side. Not only do agencies need to secure the tools they are using, but they have to defend networks against adversaries using AI-fueled cyber attacks.<\/p>\n<p>Landon Shaw, the senior architect for the Administrative Office of the U.S. Courts, said two advancements are driving the use of AI tools to secure systems and networks.<\/p>\n<p>First, agencies have done a better job of breaking down data silos, leading to a better understanding of cyber threats and risks.<\/p>\n<p>Second, Shaw said, is the rapid evolution of using multiple AI agents that work together to protect federal systems from cyber threats.<\/p>\n<p>\u201cThe biggest win for people today is to not have disjointed repositories for these different sources of data. We\u2019re seeing an advantage of taking all these different separate data source repositories for whatever type of threat intelligence data is being gathered and concatenating them into a single place, so that you can then also utilize machine learning or AI tools to get a broader picture of what\u2019s happening in your organization, so instead of trying to go and do separate searches in different databases, you can see a progression in a single location,\u201d Shaw said on the discussion <a href=\"https:\/\/federalnewsnetwork.com\/cme-event\/federal-insights\/defense-reimagined-cybersecurity-in-the-age-of-intelligent-adversaries\/\" rel=\"nofollow noopener\" target=\"_blank\">Defense Reimagined: Cybersecurity in the Age of Intelligent Adversaries<\/a>. \u201cWe\u2019ve spent a lot of time and effort over the last several years to make this reality where we don\u2019t have these separate silos. From what I\u2019ve seen, this has been the biggest change in the way we operate, giving us a single pane of glass visibility into how each of these individual systems is operating. That has been a game changer because that allows you to very quickly plug in AI tools that can find that needle in the haystack and create a case file that isn\u2019t just a single item or a single system\u2019s logs, but this case file can be a combination of 25 different data sets from 25 different security products that together can be put into a case that can be either assigned to another AI or assigned to a human to investigate, and it can also detect threats before they happen.\u201d<\/p>\n<p>Sharper sword or more solid shield<\/p>\n<p>That ability to bring threat intelligence data together has led to the ability to apply AI agents and subagents, especially as cyber attacks have grown more sophisticated and volumetric attacks can occur faster.<\/p>\n<p>\u201cNow with the ability to quickly deploy agents and subagents with frameworks like what came out from Open Claw, you can spin up subagents and you now have the ability to do this \u2018if this, then that\u2019 logic, where you can have a AI look at something and make a decision, and before that decision is implemented, you can have a subagent, another AI, check the first AI\u2019s work. Then you can have a third agent look at your rules that you defined and say, \u2018Okay, does this decision require a human in the loop, or can I implement this decision on my own?\u2019\u201d Shaw said. \u201cI think this is a big distinction because now we\u2019re not just talking about a single AI where you have to put all of your logic into and let this one AI make decisions. The last four months have changed the world with the ability to deploy rapidly, deploy agents and subagents, and you\u2019re using things like Claude for different workflows.\u201d<\/p>\n<p>The ability to use AI agents and subagents is giving agencies what Brent Hansen, the chief technology officer at Optiv + ClearShark, called either \u201ca sharper sword or a more solid shield.\u201d<\/p>\n<p>Hansen said when organizations are using AI to fight against AI-fueled attacks, it\u2019s less about better prompt engineering and all about speed.<\/p>\n<p>\u201cBeing able to do the vulnerability scanning, being able to move quicker than they\u2019ve ever been able to package and exploit vulnerabilities is challenging. But on the flip side, you\u2019re also equipped with the same toolbox and with the same expertise to be able to move quicker to plug those holes, but it\u2019s a very delicate balance of what we\u2019re empowering and what is out there on the streets,\u201d Hansen said. \u201cIt\u2019s really the continuous monitoring, evaluation, red teaming of the existing models that you have in place, so that when you do earn trust, and that trust happens either out on the edge or whether it\u2019s something internal, that is a continuous responsibility.\u201d<\/p>\n<p>This trust of AI tools and capabilities also comes from creating a data fabric that cuts across the organization.<\/p>\n<p>Hansen said this fabric becomes especially important as agencies push data to the edge.<\/p>\n<p>\u201cIt\u2019s all about the access controls and the observability to understand when it\u2019s under attack,\u201d he said. \u201cWe\u2019re better than ever at collecting data, and so with that ability, AI is able to harness that universal language to interpret lots of unstructured data, where you don\u2019t have to have everything in a very specific system log template. So that\u2019s great, we can move much quicker. When you\u2019ve got that universal data fabric, you\u2019ve got your ear to the ground, and you\u2019re able to make those detections much quicker, do better incident response, and then how do you do the enrichment of that data, so that in the rearview mirror, when there might be an incident, that you can have as much context about that particular event?\u201d<\/p>\n<p>Cyber battlefield is changing<\/p>\n<p>The need to push data to the edge and collect data at the edge means the use of a zero trust architecture to protect that information becomes even more essential.<\/p>\n<p>Kevin Walsh, the director of Information Technology and Cybersecurity for the Government Accountability Office, said with how fast data and attacks are moving, it\u2019s more difficult than ever to keep the human in the loop.<\/p>\n<p>\u201cIn that cyber battlefield, the human isn\u2019t going to have as much of a role as they do today. The only role we\u2019re going to play is in the predictive or the proactive, like setting up the guardrails and trying to be as thoughtful as we can for what that might look like, and how we want to put controls around those agents and those subagents all the way down the stack,\u201d Walsh said. \u201cWe need zero trust to make sure that those agents are acting in our organization\u2019s interest, and making sure that when they are taking those actions, sometimes we do want to give them elevated privileges, sometimes we need that to enact the appropriate defensive countermeasures, but we want it to do it thoughtfully.\u201d<\/p>\n<p>Walsh added that makes the training of the employees managing and monitoring the AI agents so much more important.<\/p>\n<p>\u201cThey have to make sure you have your multi-factor authentication set up, and all of those predictive or the preparatory steps that the humans can take, including locking down your application programming interfaces (APIs), making sure that your people are not just tongue-in-cheeking the cybersecurity training, but you are actually testing and maybe red teaming your own networks and employees to make sure that they are capable of doing the right thing,\u201d he said. \u201cI think that the human is our role is going to be changing, especially when we\u2019re talking about cybersecurity operating at machine speed. We\u2019re going to be more in a supervisory or managerial role, trying to find, which is the real attack, which needle in this haystack, or even needle in a stack of needles, is the real one we need to care about, and the real one we need to act upon, especially when we\u2019re talking about the volume that can come at us, the complexity, the battlefield is changing. We need to change with.\u201d<\/p>\n<p>Shaw said agencies have to continuously monitor and evaluate the AI agents, especially when the frontier models are changing so often.<\/p>\n<p>Models drift over time<\/p>\n<p>He said each agent needs its own identity that includes a small subset of credentials that allows them to do what they need to do.<\/p>\n<p>\u201cYou\u2019re going to monitor the AI agent, and you\u2019re going to do the trust but verify, and then once they build enough trust that they\u2019re not making ridiculous decisions, at that point you may bestow additional work on them or give them additional responsibilities,\u201d Shaw said. \u201cAn example would be to give the AI very granular rights, such as the ability to quarantine or to lock an account, but not unlock an account. For instance, the AI could log into a system if it thinks that there\u2019s an account that\u2019s been compromised and put a lock on that account, maybe that\u2019s all it can do. I think it\u2019s going to need to be the trust but verify approach, where you give very small access to these agents, monitor them, look at their thinking, make sure they\u2019re behaving correctly, and make sure you don\u2019t allow them to do any more than what you\u2019re okay with them breaking.\u201d<\/p>\n<p>Walsh added like with most technologies, you can\u2019t \u201cset it and forget it,\u201d as models do drift over time.<\/p>\n<p>Hansen said as AI continues to advance, agencies can\u2019t overlook the importance of due diligence and governance.<\/p>\n<p>\u201cIt also comes with the responsibility of ensuring that we\u2019re following zero trust principles, that we\u2019re still applying the basics around multi-factor authentication, data encryption, so keeping those basics, but also evolving them to meet the standards and the requirements of where AI is taking us and, probably more importantly, where we will take AI,\u201d he said. \u201cWhen you\u2019ve got the human in the loop, just keep that skepticism and ensure that we are using critical thinking as we\u2019re evaluating things before they are out in production, that we\u2019ve done everything possible to ensure it\u2019s equipped and ready.\u201d<\/p>\n<p class=\"article-copyright\">Copyright<br \/>\n                            \u00a9\u00a02026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.\n                    <\/p>\n","protected":false},"excerpt":{"rendered":"Watch the full discussion here. The expansion of artificial intelligence capabilities has changed the way agencies work. From&hellip;\n","protected":false},"author":2,"featured_media":103626,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[53777,24,25,32376,4770,16440,53778,53779,16665,32379,9578,53780],"class_list":["post-103625","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-administrative-office-of-the-u-s-courts","tag-ai","tag-artificial-intelligence","tag-brent-hansen","tag-government-accountability-office","tag-identity-and-access-management","tag-kevin-walsh","tag-landon-shaw","tag-multi-factor-authentication","tag-optivclearshark","tag-zero-trust","tag-zero-trust-architecture"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/103625","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=103625"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/103625\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/103626"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=103625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=103625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=103625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}